
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
flux-hooks
Advanced tools
Hooks implementation for Facebook Flux Util's Stores.
This takes advantage of the new React Hooks API, and is a great alternative to using Flux-Util's Container.
This is an implementation using a combination of useEffect & useReducer and lodash.isequal.
npm add flux-hooks or yarn add flux-hooks
const value_from_store = (prevState, store) => {...}
const value = useFluxStore(store: <FluxStore>, value_from_store: Function, deps?: Array, strictEquality?: boolean)
Using the CounterStore example from Flux Utils.
import useFluxStore from 'flux-hooks';
const CounterComponent = () => {
const counter = useFluxStore(CounterStore, (prevState, store) => store.getState())
return <CounterUI counter={counter} />;
}
The deps parameter is an Array of values as used by useCallback/useMemo.
In cases where the reducer is using other State/Prop, pass them as deps. Normally useReducer would not trigger a dispatch in this case.
import useFluxStore from 'flux-hooks';
const SearchComponent = () => {
const [query, setQuery] = useState("")
const results = useFluxStore(SearchStore, (prevState, store) => store.getSearchResults(query), [query])
return <div>
<input type="text" value={query} onChange={e => setQuery(e.target.value)} />
<ul>
results.map(r => <li>{r}</li>)
</ul>
</div>
}
Stores can update frequently with our reducer selecting only a small subset of the values. In the cases if you apply a filter on an Immutable-js objects, or return multiple values using an Object, this will cause the Object.is equality check to fail. This defeats the purpose of using the reducer!
To prevent this, lodash.isequal is used by default. This does a deep check whenever the reducer is run, to make sure nothing has changed.
The assumption here is that the equality check is cheaper to run than a re-render.
To opt out of using the more expensive lodash.isequal check set strictEquality (4th argument) to true. This will return to useReducer's default behaviour.
FAQs
Hooks implementation for Facebook Flux Util's Stores
We found that flux-hooks demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.